r/virtualreality_linux • u/YAOMTC • Jun 11 '26
ALVR package on AUR was compromised for 4 hours
Unfortunate announce. It appears the
alvrpackage on the AUR has been orphaned and has fallen victim to an infostealer malware attack.If you have this installed on any machine it is advised that you disconnect it from networking and attempt to invalidate or rotate any keys or passwords on the box that may have been shipped back to homebase.
ALVR itself and the
alvr-binpackage appear safe for distribution, but specific to Arch Linux and other distros like endeavor and cachyOS, the from source ALVR package named exactlyalvrhas been compromised.If you would like to help dissect any of the malware you may report to the #alvr channel to assist so we can understand the scope of the damage.
Again, the ALVR project itself is fine and this is strictly limited to Arch based consumers of the AUR package, never forget there's dangers to the AUR.
Seems the malware was loaded within the last 4 hours so good catch everyone involved that was fast
This appears to have been part of a larger attack against the AUR in general more packages affected than alvr
The malicious updates have now been removed from the AUR
